Your backups contain the same sensitive data that you encrypt in your production org.
It makes sense to protect backups the same way. Shield Platform Encryption extends to Backup
& Recover Next and encrypts backup data at rest with a root key that's unique to your org.
As a result, your backup data meets the same compliance and regulatory requirements as your
production data.
Required Editions
Available in both Lightning Experience and Salesforce Classic (not available in
all orgs).
Available in: Enterprise, Performance, Unlimited, and
Developer Editions. Requires purchasing Salesforce Shield or Shield
Platform Encryption, and the Backup & Recover Data and Backup & Recover
Files add-on licenses.
Encryption for Backup & Recover Next uses a two-tier key architecture. You control a
Backup & Recover root key, which Salesforce then uses to protect the data encryption keys
(DEKs) that encrypt data backups at rest. Generate your root key with Salesforce, or use Bring
Your Own Key (BYOK) to generate a root key outside Salesforce and then upload it. Manage your
root key in Setup or through the API, including key rotation. All Salesforce-generated and
customer-supplied key material is visible on the Key Management page for auditing.
Note Backup & Recover root keys encrypt backups made with Salesforce Backup & Recover
Next. These root keys don’t encrypt data backups made with Backup & Recover for Salesforce
or the legacy Salesforce Backup.
Your Backup & Recover root key encrypts all backups created after you activated your root
key. Earlier backups remain unencrypted. If you’re new to Backup & Recover Next, generate
a root key before your first backup.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.